The Digital Operational Resilience Act entered into application on 17 January 2025, and for most of that first year, supervisory activity was described — by regulators themselves — as a period of tolerance. Institutions were expected to have programmes in place, but National Competent Authorities were largely reviewing documentation rather than testing whether the resilience measures actually worked under stress. That tolerance period is over. Legal commentary through 2026 has been consistent on one point: a DORA programme that was adequate for a January 2025 supervisory conversation is not adequate for a 2026 examination.
What changed is not the text of the regulation but the expectation of evidence. Supervisors are now asking for real-time proof of ICT risk management rather than a policy binder — demonstrable control over incident response, defensible data lineage for the fields institutions are required to report, and evidence that resilience testing (including the threat-led penetration testing DORA requires for the most significant entities) actually happened rather than merely being scheduled.
DORA also extended its reach beyond the financial institutions it obviously targets. In November 2025, the European Supervisory Authorities designated nineteen firms as 'critical' ICT third-party providers subject to direct oversight — a list that includes Amazon, Google, and IBM. This is a genuinely unusual regulatory move: cloud and technology providers who are not themselves financial institutions, brought under direct supervision because the financial sector's operational resilience now depends on their infrastructure. A bank can have a flawless DORA programme and still be exposed if its cloud provider's own resilience posture is weak — which is exactly the systemic risk this designation is built to address.
For institutions and their ICT suppliers, including non-EU firms with EU-facing operations, the practical shift for 2026 is treating DORA not as a compliance project with a finish line but as an ongoing supervisory relationship — closer in character to prudential regulation than to a one-time certification.